LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0402: OSX/Shlayer

OSX/Shlayer is a Trojan designed to install adware on macOS that was first discovered in 2018.[1][2]

EnterpriseS0402MalwareObject v1.4Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

OSX/Shlayer matters because it represents a macOS Trojan pattern that can turn user-driven execution into adware installation while using macOS-specific evasion and persistence behaviors. For leaders, the practical issue is not only “malware on Macs,” but whether the organization can see and control script execution, downloaded files, browser extension changes, privilege prompts, Gatekeeper-related events, hidden artifacts, and unexpected file transfers on macOS endpoints.

Executive priority

Treat this as a macOS endpoint resilience and evidence-readiness issue. If Macs are used by executives, developers, finance, or privileged administrators, gaps in macOS logging, endpoint management, browser extension governance, and user privilege controls can leave SOC and IR teams with weak evidence during an incident. Priority should go to validating macOS EDR/MDM coverage, browser extension inventory, least-privilege enforcement, and response playbooks for suspicious downloads, shell execution, and privilege prompts.

Technical view

ATT&CK provides no official detection text for OSX/Shlayer, so defenders should build validation around the related techniques: user-opened malicious files, Unix shell execution, system and file discovery, ingress tool transfer, deobfuscation, browser extension persistence, permission changes, elevated execution prompts, Gatekeeper bypass behavior, and macOS artifact hiding including hidden files, resource forks, and ignored process interrupts. SOC teams should confirm they can correlate a downloaded or user-launched file with child shell processes, network retrieval of additional files, changes to browser extensions or configuration profiles where visible, permission or extended-attribute changes, and suspicious placement or naming that resembles legitimate resources.

Likely telemetry

  • macOS endpoint process creation and command-line telemetry, especially sh/bash/zsh activity spawned by downloaded or user-launched files
  • File creation, modification, rename, permission, hidden attribute, and extended attribute telemetry on macOS
  • Browser extension inventory and change events across managed browsers
  • MDM or endpoint management evidence for Gatekeeper, quarantine, notarization-related policy state, and configuration changes where available
  • Network telemetry for external file downloads or tool transfer from macOS hosts

Detection direction

  • Validate macOS-specific visibility rather than assuming Windows-centric endpoint rules apply.
  • Correlate user execution of downloaded files with shell child processes, discovery commands, external downloads, permission changes, and hidden artifact creation.
  • Tune for suspicious browser extension installation or modification, while accounting for legitimate enterprise-managed extensions.
  • Review events involving Gatekeeper bypass indicators, quarantine or extended attribute changes, and resource fork usage, recognizing that some administrative or developer workflows may create false positives.
  • Look for files placed in trusted-looking locations or named to resemble legitimate resources, especially when paired with recent download, shell execution, or network retrieval activity.

Mitigation priorities

  • Ensure macOS endpoints are enrolled in managed endpoint security and MDM with auditable policy enforcement.
  • Limit routine administrator privileges and review workflows that train users to approve unexpected elevated execution prompts.
  • Enforce controlled software download and execution policies, including Gatekeeper and quarantine-related protections where appropriate.
  • Govern browser extensions through inventory, allowlisting or approval processes, and periodic review.
  • Collect and retain macOS process, file, network, browser, and management telemetry needed for incident reconstruction.
Additional notes and limits

The relationship set makes this object useful for coverage assessment across macOS execution, persistence, privilege escalation, defense impairment, discovery, command-and-control, and stealth behaviors. The strongest defensive value is to use OSX/Shlayer as a macOS control-validation scenario: can the team prove what ran, what it downloaded, what it changed, whether it requested elevation, and whether it persisted through browser-related mechanisms?

MITRE does not provide official detection guidance, tactics are not specified on the malware object, and the supplied description is brief. This take is therefore based on the official description, external references, platform field, and ATT&CK relationships only. Local telemetry, endpoint configuration, browser fleet data, and user privilege models are required to determine actual exposure or coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

OSX/Shlayer

OSX/Shlayer is a Trojan designed to install adware on macOS that was first discovered in 2018.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

15 rows
DomainIDNameRelationship / procedure
EnterpriseT1564Hide Artifacts

OSX/Shlayer has used the mktemp utility to make random and unique filenames for payloads, such as export tmpDir="$(mktemp -d /tmp/XXXXXXXXXXXX)" or mktemp -t Installer.[3][4][5]

EnterpriseT1564.001Hidden Files and DirectoriesSub-technique

OSX/Shlayer has executed a .command script from a hidden directory in a mounted DMG.[1]

EnterpriseT1222.002Linux and Mac PermissionsSub-technique

OSX/Shlayer can use the chmod utility to set a file as executable, such as chmod 777 or chmod +x.[4][1][5]

EnterpriseT1204.002Malicious FileSub-technique

OSX/Shlayer has relied on users mounting and executing a malicious DMG file.[1][2]

EnterpriseT1176.001Browser ExtensionsSub-technique

OSX/Shlayer can install malicious Safari browser extensions to serve ads.[6][7]

EnterpriseT1553.001Gatekeeper BypassSub-technique

If running with elevated privileges, OSX/Shlayer has used the spctl command to disable Gatekeeper protection for a downloaded file. OSX/Shlayer can also leverage system links pointing to bash scripts in the downloaded DMG file to bypass Gatekeeper, a flaw patched in macOS 11.3 and later versions. OSX/Shlayer has been Notarized by Apple, resulting in successful passing of additional Gatekeeper checks.[1][5][8]

EnterpriseT1059.004Unix ShellSub-technique

OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command sh -c tail -c +1381... to extract bytes at an offset from a specified file. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.[1][3][4][8]

EnterpriseT1564.011Ignore Process InterruptsSub-technique

OSX/Shlayer has used the `nohup` command to instruct executed payloads to ignore hangup signals.[5]

EnterpriseT1140Deobfuscate/Decode Files or Information

OSX/Shlayer can base64-decode and AES-decrypt downloaded payloads.[1] Versions of OSX/Shlayer pass encrypted and password-protected code to openssl and then write the payload to the /tmp folder.[3][4]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

OSX/Shlayer can masquerade as a Flash Player update.[1][2]

EnterpriseT1564.009Resource ForkingSub-technique

OSX/Shlayer has used a resource fork to hide a compressed binary file of itself from the terminal, Finder, and potentially evade traditional scanners.[9][10]

EnterpriseT1083File and Directory Discovery

OSX/Shlayer has used the command appDir="$(dirname $(dirname "$currentDir"))" and $(dirname "$(pwd -P)") to construct installation paths.[3][4]

EnterpriseT1082System Information Discovery

OSX/Shlayer has collected the IOPlatformUUID, session UID, and the OS version using the command sw_vers -productVersion.[1][3]

EnterpriseT1105Ingress Tool Transfer

OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.[1][3][4][8]

EnterpriseT1548.004Elevated Execution with PromptSub-technique

OSX/Shlayer can escalate privileges to root by asking the user for credentials.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.4
Created
Modified
Raw hash
0086df520da8553c...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.4Current bundle0086df520da8…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  2. [2]
    Intego Shlayer Feb 2018

    Long, Joshua. (2018, February 21). OSX/Shlayer: New Mac malware comes out of its shell. Retrieved August 28, 2019.

    Open source URL
  3. [3]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  4. [4]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  5. [5]
    Shlayer jamf gatekeeper bypass 2021

    Jaron Bradley. (2021, April 26). Shlayer malware abusing Gatekeeper bypass on macOS. Retrieved September 22, 2021.

    Open source URL
  6. [6]
    Intego Shlayer Apr 2018

    Vrijenhoek, Jay. (2018, April 24). New OSX/Shlayer Malware Variant Found Using a Dirty New Trick. Retrieved September 6, 2019.

    Open source URL
  7. [7]
    Malwarebytes Crossrider Apr 2018

    Reed, Thomas. (2018, April 24). New Crossrider variant installs configuration profiles on Macs. Retrieved September 6, 2019.

    Open source URL
  8. [8]
    objectivesee osx.shlayer apple approved 2020

    Patrick Wardle. (2020, August 30). Apple Approved Malware malicious code ...now notarized!? #2020. Retrieved September 13, 2021.

    Open source URL
  9. [9]
    tau bundlore erika noerenberg 2020

    Erika Noerenberg. (2020, June 29). TAU Threat Analysis: Bundlore (macOS) mm-install-macos. Retrieved October 12, 2021.

    Open source URL
  10. [10]
    sentinellabs resource named fork 2020

    Phil Stokes. (2020, November 5). Resourceful macOS Malware Hides in Named Fork. Retrieved October 12, 2021.

    Open source URL
  11. [11]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  12. [12]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  13. [13]
    Crossrider

    (Citation: Intego Shlayer Apr 2018)(Citation: Malwarebytes Crossrider Apr 2018)

  14. [14]
    Crossrider

    (Citation: Intego Shlayer Apr 2018)(Citation: Malwarebytes Crossrider Apr 2018)

  15. [15]
    Crossrider

    (Citation: Intego Shlayer Apr 2018)(Citation: Malwarebytes Crossrider Apr 2018)

  16. [16]
    Intego Shlayer Apr 2018

    Vrijenhoek, Jay. (2018, April 24). New OSX/Shlayer Malware Variant Found Using a Dirty New Trick. Retrieved September 6, 2019.

    Open source URL
  17. [17]
    Intego Shlayer Apr 2018

    Vrijenhoek, Jay. (2018, April 24). New OSX/Shlayer Malware Variant Found Using a Dirty New Trick. Retrieved September 6, 2019.

    Open source URL
  18. [18]
    Intego Shlayer Feb 2018

    Long, Joshua. (2018, February 21). OSX/Shlayer: New Mac malware comes out of its shell. Retrieved August 28, 2019.

    Open source URL
  19. [19]
    Intego Shlayer Feb 2018

    Long, Joshua. (2018, February 21). OSX/Shlayer: New Mac malware comes out of its shell. Retrieved August 28, 2019.

    Open source URL
  20. [20]
    Malwarebytes Crossrider Apr 2018

    Reed, Thomas. (2018, April 24). New Crossrider variant installs configuration profiles on Macs. Retrieved September 6, 2019.

    Open source URL
  21. [21]
    Malwarebytes Crossrider Apr 2018

    Reed, Thomas. (2018, April 24). New Crossrider variant installs configuration profiles on Macs. Retrieved September 6, 2019.

    Open source URL
  22. [22]
    OSX/Shlayer

    (Citation: Carbon Black Shlayer Feb 2019)(Citation: Intego Shlayer Feb 2018)

  23. [23]
    OSX/Shlayer

    (Citation: Carbon Black Shlayer Feb 2019)(Citation: Intego Shlayer Feb 2018)

  24. [24]
    OSX/Shlayer

    (Citation: Carbon Black Shlayer Feb 2019)(Citation: Intego Shlayer Feb 2018)

  25. [25]
    Zshlayer

    (Citation: sentinelone shlayer to zshlayer)

  26. [26]
    Zshlayer

    (Citation: sentinelone shlayer to zshlayer)

  27. [27]
    Zshlayer

    (Citation: sentinelone shlayer to zshlayer)

  28. [28]
    mitre-attackS0402
    Open source URL
  29. [29]
    mitre-attackS0402
    Open source URL
  30. [30]
    mitre-attackS0402
    Open source URL
  31. [31]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  32. [32]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  33. [33]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  34. [34]
    Shlayer jamf gatekeeper bypass 2021

    Jaron Bradley. (2021, April 26). Shlayer malware abusing Gatekeeper bypass on macOS. Retrieved September 22, 2021.

    Open source URL
  35. [35]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  36. [36]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  37. [37]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  38. [38]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  39. [39]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  40. [40]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  41. [41]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  42. [42]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  43. [43]
    Shlayer jamf gatekeeper bypass 2021

    Jaron Bradley. (2021, April 26). Shlayer malware abusing Gatekeeper bypass on macOS. Retrieved September 22, 2021.

    Open source URL
  44. [44]
    Shlayer jamf gatekeeper bypass 2021

    Jaron Bradley. (2021, April 26). Shlayer malware abusing Gatekeeper bypass on macOS. Retrieved September 22, 2021.

    Open source URL
  45. [45]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  46. [46]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  47. [47]
    Intego Shlayer Feb 2018

    Long, Joshua. (2018, February 21). OSX/Shlayer: New Mac malware comes out of its shell. Retrieved August 28, 2019.

    Open source URL
  48. [48]
    Intego Shlayer Feb 2018

    Long, Joshua. (2018, February 21). OSX/Shlayer: New Mac malware comes out of its shell. Retrieved August 28, 2019.

    Open source URL
  49. [49]
    Intego Shlayer Apr 2018

    Vrijenhoek, Jay. (2018, April 24). New OSX/Shlayer Malware Variant Found Using a Dirty New Trick. Retrieved September 6, 2019.

    Open source URL
  50. [50]
    Intego Shlayer Apr 2018

    Vrijenhoek, Jay. (2018, April 24). New OSX/Shlayer Malware Variant Found Using a Dirty New Trick. Retrieved September 6, 2019.

    Open source URL
  51. [51]
    Malwarebytes Crossrider Apr 2018

    Reed, Thomas. (2018, April 24). New Crossrider variant installs configuration profiles on Macs. Retrieved September 6, 2019.

    Open source URL
  52. [52]
    Malwarebytes Crossrider Apr 2018

    Reed, Thomas. (2018, April 24). New Crossrider variant installs configuration profiles on Macs. Retrieved September 6, 2019.

    Open source URL
  53. [53]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  54. [54]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  55. [55]
    Shlayer jamf gatekeeper bypass 2021

    Jaron Bradley. (2021, April 26). Shlayer malware abusing Gatekeeper bypass on macOS. Retrieved September 22, 2021.

    Open source URL
  56. [56]
    Shlayer jamf gatekeeper bypass 2021

    Jaron Bradley. (2021, April 26). Shlayer malware abusing Gatekeeper bypass on macOS. Retrieved September 22, 2021.

    Open source URL
  57. [57]
    objectivesee osx.shlayer apple approved 2020

    Patrick Wardle. (2020, August 30). Apple Approved Malware malicious code ...now notarized!? #2020. Retrieved September 13, 2021.

    Open source URL
  58. [58]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  59. [59]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  60. [60]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  61. [61]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  62. [62]
    objectivesee osx.shlayer apple approved 2020

    Patrick Wardle. (2020, August 30). Apple Approved Malware malicious code ...now notarized!? #2020. Retrieved September 13, 2021.

    Open source URL
  63. [63]
    objectivesee osx.shlayer apple approved 2020

    Patrick Wardle. (2020, August 30). Apple Approved Malware malicious code ...now notarized!? #2020. Retrieved September 13, 2021.

    Open source URL
  64. [64]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  65. [65]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  66. [66]
    Shlayer jamf gatekeeper bypass 2021

    Jaron Bradley. (2021, April 26). Shlayer malware abusing Gatekeeper bypass on macOS. Retrieved September 22, 2021.

    Open source URL
  67. [67]
    Shlayer jamf gatekeeper bypass 2021

    Jaron Bradley. (2021, April 26). Shlayer malware abusing Gatekeeper bypass on macOS. Retrieved September 22, 2021.

    Open source URL
  68. [68]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  69. [69]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  70. [70]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  71. [71]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  72. [72]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  73. [73]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  74. [74]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  75. [75]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  76. [76]
    Intego Shlayer Feb 2018

    Long, Joshua. (2018, February 21). OSX/Shlayer: New Mac malware comes out of its shell. Retrieved August 28, 2019.

    Open source URL
  77. [77]
    Intego Shlayer Feb 2018

    Long, Joshua. (2018, February 21). OSX/Shlayer: New Mac malware comes out of its shell. Retrieved August 28, 2019.

    Open source URL
  78. [78]
    sentinellabs resource named fork 2020

    Phil Stokes. (2020, November 5). Resourceful macOS Malware Hides in Named Fork. Retrieved October 12, 2021.

    Open source URL
  79. [79]
    tau bundlore erika noerenberg 2020

    Erika Noerenberg. (2020, June 29). TAU Threat Analysis: Bundlore (macOS) mm-install-macos. Retrieved October 12, 2021.

    Open source URL
  80. [80]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  81. [81]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  82. [82]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  83. [83]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  84. [84]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  85. [85]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  86. [86]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  87. [87]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  88. [88]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  89. [89]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  90. [90]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  91. [91]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  92. [92]
    objectivesee osx.shlayer apple approved 2020

    Patrick Wardle. (2020, August 30). Apple Approved Malware malicious code ...now notarized!? #2020. Retrieved September 13, 2021.

    Open source URL
  93. [93]
    objectivesee osx.shlayer apple approved 2020

    Patrick Wardle. (2020, August 30). Apple Approved Malware malicious code ...now notarized!? #2020. Retrieved September 13, 2021.

    Open source URL
  94. [94]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  95. [95]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  96. [96]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
  97. [97]
    Carbon Black Shlayer Feb 2019

    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.